Create a logs alert :: Kloudfuse Docs

Create a logs alert

Log monitors generate alerts when a specified a specific pattern or condition is detected within log data—when something unusual or potentially problematic happens within the system, based on information recorded in logs.

To create a log alert, complete these tasks:

Start defining a log alert

  1. In the Alerts interface, click (Create New Alert).

  2. In the initial interface for creating alerts, Kloudfuse guides you to select the appropriate alert type.

Choose Log.

  1. The Create Log Alert interface appears.

Pick log metric

  1. Click the initial text field (a) to Search logs.

  2. The log search interface appears.

Examples on how to search:

  1. You can also pick the labels from the drop-down, and assign values to them.

  2. As you select search terms, Kloudfuse adds them to the log query.

  3. To remove a search term that you previously selected, click (Delete) icon on that tile.

  4. To remove all search terms that you previously selected, click the (Delete) icon on the right side of the drop-down.

  5. After you pick a log metric, Kloudfuse displays it in the chart.

Work with queries

  1. Make optional changes to filter and configure your log metric search:

  2. In the (Show count of) drop-down, select all logs, all fingerprints, or one of the many prepared labels.

  3. In the (by) drop-down, choose Everything, or one of the many prepared labels.

  4. In the (limit to) drop-down, select either (bottom) or (top), and specify the number of records to show: 2, 5, 10, 15, 25, 30, 50, or 100.

  5. In the (roll up every) drop-down, select time-based grouping: 15 seconds (default), 20 seconds, 30 seconds, 1 minute, or 2 minutes.

  6. To remove a query, click the (Delete) icon that corresponds to this query.

Work with formulas

Add formula

You can combine metrics over facets or labels into formulas, to get additional insights.

  1. To add a formula, click (Add Formula).

  2. The empty formula option appears in interface as line (1), under the query lines.

  3. Type the formula in the text box next to label (1).

  4. To remove a formula, click the (Delete) icon that corresponds to this formula.

Set condition

  1. Define the condition that triggers the alert:

  2. From the first drop-down, select the condition function: Mean, Min, Max, Sum, Count, or Last (default).

  3. From the second drop-down, select the evaluated query ( Query (a), Query (b), and so on) or formula ( Formula (1), Formula (2), and so on).

  4. From the third drop-down, select the comparison operator: above (default), below, equal to, not equal to, above or equal to, or below or equal to.

  5. [Optional] In the text box, specify the unit of measurement.

  6. In the fourth (last) drop-down, specify the time interval: 5 minutes, 10 minutes, 15 minutes, 30 minutes, 1 hour, 2 hours, 4 hours, or 1 day.

  7. Expand the Configure no data and error handling option.

No data
What to do when data is missing.

In the first drop-down, select one of the options: Alerting, No data, or OK (default).

Error handling
What to do when there is an execution error, or a timeout.

In the second drop-down, select one of the options: Alerting, OK, or Error (default).

Add details

  1. In the Folder name drop-down, select one of the folders.

Alternatively, click the (Create new folder) icon.

Then, in the Create Folder dialog, specify Folder name, and click (Create new folder).

  1. In Rule name, specify the name of your rule.

  2. [Optional] In Title, enter the title of your rule.

  3. [Optional] In Runbook URL, enter the location of the runbook that specifies how to handle the alert.

  4. [Optional] Under Desription, specify the purpose of the rule, what conditions it should catch, and so on.

  5. [Optional] Under Custom labels, click (plus), and specify the custom label name, and its value.

To add more custom labels, click (plus), and specify more custom labels.

To remove a custom label, click (Trash) next to it.

  1. [Optional] Under Custom annotations, click (plus), and specify the custom annotation name, and its value.

To add more custom annotations, click (plus), and specify more custom annotations.

To remove a custom annotation, click (Trash) next to it.

Use annotations to show different alerts and their visualizations.

Add contacts

Choose contact points

  1. Choose one or more of the existing contacts from the drop-down, so they can receive the alert.

  2. To remove a contact you previously selected from the alert notification, click (Delete) icon on their tile.

  3. To remove all contacts that you previously selected, click the (Delete) icon on the right side of the drop-down.

Create new contact points

  1. Click (Create New Contact Points).

  2. Kloudfuse opens the Create Contact points interface.

Specify, configure, test, and save new contact points. See Alerts contact points for details.

Create rule

  1. To finalize, click (Create Rule).

  2. Depending on your choice of calculation when you Set condition (, , , , and so on) Kloudfuse generates a Confirm Query Selection dialog.

  3. In the Confirm Query Selection dialog, click

  4. You get a confirmation message.